Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package melange for openSUSE:Factory checked in at 2026-09-21 12:23:04 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/melange (Old) and /work/SRC/openSUSE:Factory/.melange.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "melange" Mon Sep 21 12:23:04 2026 rev:179 rq:1379352 version:0.61.1 Changes: -------- --- /work/SRC/openSUSE:Factory/melange/melange.changes 2026-09-19 22:22:54.501023415 +0200 +++ /work/SRC/openSUSE:Factory/.melange.new.383539/melange.changes 2026-09-21 12:23:33.481141143 +0200 @@ -1,0 +2,10 @@ +Mon Sep 21 05:11:16 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 0.61.1: + * build(deps): bump + go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp + (#2659) + * fix(git-checkout): retry the tag fetch, not just the clone + (#2661) + +------------------------------------------------------------------- Old: ---- melange-0.61.0.obscpio New: ---- melange-0.61.1.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ melange.spec ++++++ --- /var/tmp/diff_new_pack.j3RRCf/_old 2026-09-21 12:23:35.199212948 +0200 +++ /var/tmp/diff_new_pack.j3RRCf/_new 2026-09-21 12:23:35.201213031 +0200 @@ -17,7 +17,7 @@ Name: melange -Version: 0.61.0 +Version: 0.61.1 Release: 0 Summary: Build APKs from source code License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.j3RRCf/_old 2026-09-21 12:23:35.238214578 +0200 +++ /var/tmp/diff_new_pack.j3RRCf/_new 2026-09-21 12:23:35.241214703 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/chainguard-dev/melange.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v0.61.0</param> + <param name="revision">refs/tags/v0.61.1</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.j3RRCf/_old 2026-09-21 12:23:35.263215623 +0200 +++ /var/tmp/diff_new_pack.j3RRCf/_new 2026-09-21 12:23:35.266215748 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/chainguard-dev/melange</param> <param name="changesrevision">3f6115b820985d70ca3c93cdf8519c1b3b4cfe81</param></service><service name="tar_scm"> <param name="url">https://github.com/chainguard-dev/melange.git</param> - <param name="changesrevision">7333a9a49274adf01c4c5a6cffcaaefcaa4f76d1</param></service></servicedata> + <param name="changesrevision">d062cf25ce373bf8045d79b9897878ab207d8d36</param></service></servicedata> (No newline at EOF) ++++++ melange-0.61.0.obscpio -> melange-0.61.1.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/melange-0.61.0/e2e-tests/git-checkout-build.yaml new/melange-0.61.1/e2e-tests/git-checkout-build.yaml --- old/melange-0.61.0/e2e-tests/git-checkout-build.yaml 2026-09-17 23:47:57.000000000 +0200 +++ new/melange-0.61.1/e2e-tests/git-checkout-build.yaml 2026-09-20 23:39:16.000000000 +0200 @@ -326,6 +326,40 @@ cd .. rm -R cherry-pick-test + # The tag path does two network operations -- the clone and then a fetch of + # the tag refspec -- and both must survive a flaky remote. install-flaky-git + # shims git so the first 3 tag fetches fail the way gitlab.com does when it + # sheds load; the checkout is only reachable if the fetch is retried. + - name: "make the next 3 tag fetches fail" + runs: | + ./install-flaky-git 3 + + - name: "tag fetch retried on transient remote failure" + uses: git-checkout + working-directory: flaky-tag-fetch + with: + repository: ${{vars.giturl}} + tag: 2.0 + expected-commit: 3dfc3dd573b814be48c07f7f8ae3c19a23b69865 + max-retries: 5 + initial-backoff: 1 + max-backoff: 2 + + - name: "check tag fetch retried on transient remote failure" + working-directory: flaky-tag-fetch + runs: | + hash=$(git rev-parse --verify HEAD) + [ "$hash" = 3dfc3dd573b814be48c07f7f8ae3c19a23b69865 ] + # 3 injected failures + 1 success: anything less means the fetch was not + # retried, anything more means it retried when it should have stopped. + read attempts < /tmp/flaky-git.attempts + [ "$attempts" = 4 ] || + { echo "expected 4 tag fetch attempts, got $attempts"; exit 1; } + cd .. + ./install-flaky-git --uninstall + rm -f /tmp/flaky-git.attempts + rm -R flaky-tag-fetch + # When ownership of files created inside and outside of the runner container do not # match, if mode is restrictive on files like 0700 on the Melange workspace, if the git-checkout # pipeline changes ownership on them, being that it runs inside the runner container, subsequent diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/melange-0.61.0/e2e-tests/test-fixtures/install-flaky-git new/melange-0.61.1/e2e-tests/test-fixtures/install-flaky-git --- old/melange-0.61.0/e2e-tests/test-fixtures/install-flaky-git 1970-01-01 01:00:00.000000000 +0100 +++ new/melange-0.61.1/e2e-tests/test-fixtures/install-flaky-git 2026-09-20 23:39:16.000000000 +0200 @@ -0,0 +1,53 @@ +#!/bin/sh +# Install a "git" wrapper earlier on PATH that makes the first N fetches of a +# tag refspec fail the way gitlab.com does when it is shedding load, then gets +# out of the way. Used by git-checkout-build.yaml to check that the pipeline +# retries the tag fetch rather than dying on the first failure. +# +# Usage: ./install-flaky-git [num-failures] ; ./install-flaky-git --uninstall +set -e + +# SHIM/CFILE are overridable so this can be exercised outside a build env. +SHIM=${FLAKY_GIT_SHIM:-/usr/local/bin/git} +CFILE=${FLAKY_GIT_ATTEMPTS:-/tmp/flaky-git.attempts} + +if [ "$1" = "--uninstall" ]; then + rm -f "$SHIM" + exit 0 +fi + +fails=${1:-3} + +# Resolve the real git *before* the shim exists, otherwise the shim would +# find itself and recurse. +real=$(command -v git) || { echo "no git on PATH" 1>&2; exit 1; } +case "$real" in + "$SHIM") echo "shim already installed at $real" 1>&2; exit 1;; +esac + +mkdir -p "${SHIM%/*}" +rm -f "$CFILE" + +cat > "$SHIM" <<EOF +#!/bin/sh +# test shim installed by install-flaky-git -- fails the first $fails tag fetches +for a in "\$@"; do + case "\$a" in + +refs/tags/*) + n=0 + [ -f "$CFILE" ] && read n < "$CFILE" + n=\$((n + 1)) + echo "\$n" > "$CFILE" + if [ "\$n" -le $fails ]; then + echo "fatal: remote error: GitLab is currently unable to handle" \\ + "this request due to load (ID testshim\$n-ORD)." 1>&2 + exit 128 + fi + ;; + esac +done +exec "$real" "\$@" +EOF + +chmod 755 "$SHIM" +echo "installed flaky git shim at $SHIM (first $fails tag fetches will fail)" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/melange-0.61.0/e2e-tests/test-fixtures/melange-created.lst new/melange-0.61.1/e2e-tests/test-fixtures/melange-created.lst --- old/melange-0.61.0/e2e-tests/test-fixtures/melange-created.lst 2026-09-17 23:47:57.000000000 +0200 +++ new/melange-0.61.1/e2e-tests/test-fixtures/melange-created.lst 2026-09-20 23:39:16.000000000 +0200 @@ -144,6 +144,7 @@ ./.melange.fdo.h ./.melange.gcc.spec ./create-git-repo +./install-flaky-git ./melange-created.lst ./melange-out ./melange-out/test-git-checkout diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/melange-0.61.0/go.mod new/melange-0.61.1/go.mod --- old/melange-0.61.0/go.mod 2026-09-17 23:47:57.000000000 +0200 +++ new/melange-0.61.1/go.mod 2026-09-20 23:39:16.000000000 +0200 @@ -153,7 +153,7 @@ go.opentelemetry.io/auto/sdk v1.2.1 // indirect go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.71.0 // indirect go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0 // indirect - go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 // indirect + go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.45.0 // indirect go.opentelemetry.io/otel/metric v1.46.0 // indirect go.opentelemetry.io/otel/trace v1.46.0 // indirect go.step.sm/crypto v0.90.0 // indirect diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/melange-0.61.0/go.sum new/melange-0.61.1/go.sum --- old/melange-0.61.0/go.sum 2026-09-17 23:47:57.000000000 +0200 +++ new/melange-0.61.1/go.sum 2026-09-20 23:39:16.000000000 +0200 @@ -361,10 +361,10 @@ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0/go.mod h1:085m8qbm4hgc8rZWGDEa4vmyyo2c3nPxUslYUKUIU04= go.opentelemetry.io/otel v1.46.0 h1:FHt5/CDyVxi/8IM1CH7VE/rRgq3kLHa2mSTVMO8AWyc= go.opentelemetry.io/otel v1.46.0/go.mod h1:Gj3SEScelsNC45tp4nSxRYlS+f5iez7W8XPMCt905kE= -go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 h1:4YsVu3B8+3qtWYYrsUYgn0OG78pN0rnNPRGX4SbokQI= -go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0/go.mod h1:+wnlSn0mD1ADVMe3v9Z/WIaiz6q6gL2J/ejaAmdmv80= -go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 h1:3iZJKlCZufyRzPzlQhUIWVmfltrXuGyfjREgGP3UUjc= -go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0/go.mod h1:/G+nUPfhq2e+qiXMGxMwumDrP5jtzU+mWN7/sjT2rak= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.45.0 h1:QRefszxJmfPdjXUUm3j6iDzY03mTPXMjqErFqQ67vUg= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.45.0/go.mod h1:Tiz03lTBVBrm7eWZBOidzEaYaJa8tjwGUGv6d8mlTyk= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.45.0 h1:QBajQ2SrwQijzHyZbQlPsuIzpl/ll8DY6wPWsajeGcI= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.45.0/go.mod h1:08ZQLjrPLQ6R4kAXvuOvODEer5Yh4CoFvll5qB2BCI8= go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.46.0 h1:KdRxPiAoMptR3vfWzvjjvutTsSiwbC2uG0496rzZNfo= go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.46.0/go.mod h1:K/qSA+3G7Eovxi4K09wzrAgkWRnosS0DAOZeEpve7sM= go.opentelemetry.io/otel/metric v1.46.0 h1:yBnkXvgV7AXFILZc5K6IZe/CBFF3OS7BJ8ov6/lj0K8= @@ -375,8 +375,8 @@ go.opentelemetry.io/otel/sdk/metric v1.46.0/go.mod h1:I1PbKrdVc8Qu8HYVDNtqVIwLwjNrhsV/uFuxfwg8mO4= go.opentelemetry.io/otel/trace v1.46.0 h1:OULy7ccdJnZtJ0UDYFOIGaCmiWzJ8Vi2G/Rsu60qs1c= go.opentelemetry.io/otel/trace v1.46.0/go.mod h1:J7GAXweO77XSFkB/rmAqk9D6ihszhFjLU+d9WuUxDLI= -go.opentelemetry.io/proto/otlp v1.10.0 h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g= -go.opentelemetry.io/proto/otlp v1.10.0/go.mod h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk= +go.opentelemetry.io/proto/otlp v1.11.0 h1:5rrYs0Ykyj50sdU/JU0x8etU+LubXWb+gED6TbEdMIk= +go.opentelemetry.io/proto/otlp v1.11.0/go.mod h1:SmVizdCOAm3XBtG1g1NnOdhW6jtddT72hLMhv8VwA8E= go.step.sm/crypto v0.90.0 h1:ZEWK0Ly0RyEC2S2OP1+N/SRbTRU+sW7go0tttHgyXkw= go.step.sm/crypto v0.90.0/go.mod h1:dgT4uZ4cClpjCi6HZZAmLomgn5tOfpHTqb34lTFN2PQ= go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto= diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/melange-0.61.0/pkg/build/pipelines/git-checkout.yaml new/melange-0.61.1/pkg/build/pipelines/git-checkout.yaml --- old/melange-0.61.0/pkg/build/pipelines/git-checkout.yaml 2026-09-17 23:47:57.000000000 +0200 +++ new/melange-0.61.1/pkg/build/pipelines/git-checkout.yaml 2026-09-20 23:39:16.000000000 +0200 @@ -402,8 +402,11 @@ # git clone --branch=X will pick the branch X if there # exists both a tag and a branch by that name. # since a tag was given, we want the tag. - vr git fetch $quiet $remote ${depthflag:+"${depthflag}"} --no-tags \ - "+refs/tags/$tag:refs/$remote/tags/$tag" + # shellcheck disable=SC2086 + retry_with_backoff "$max_retries" "$initial_backoff" "$max_backoff" \ + vr git fetch $quiet $remote ${depthflag:+"${depthflag}"} --no-tags \ + "+refs/tags/$tag:refs/$remote/tags/$tag" || + fail "git fetch of tag $tag failed after $max_retries retries" vr git checkout $quiet "$remote/tags/$tag" foundcommit=$(git rev-parse --verify HEAD) ++++++ melange.obsinfo ++++++ --- /var/tmp/diff_new_pack.j3RRCf/_old 2026-09-21 12:23:36.488266823 +0200 +++ /var/tmp/diff_new_pack.j3RRCf/_new 2026-09-21 12:23:36.491266948 +0200 @@ -1,5 +1,5 @@ name: melange -version: 0.61.0 -mtime: 1789681677 -commit: 7333a9a49274adf01c4c5a6cffcaaefcaa4f76d1 +version: 0.61.1 +mtime: 1789940356 +commit: d062cf25ce373bf8045d79b9897878ab207d8d36 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/melange/vendor.tar.gz /work/SRC/openSUSE:Factory/.melange.new.383539/vendor.tar.gz differ: char 134, line 1
